perplexity
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the skill’s required runtime, the outsider-authored
input/query(user text) is sent to Perplexity to perform web search and generate answers, so attacker-controlled text can influence retrieved outsider web content that the model consumes (viaweb_searchtools and returned grounding snippets/answer text).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata